Skip to main navigation Skip to search Skip to main content

Credential Issuance Transparency: A Privacy-preserving Audit Log of Credential Issuance

Research output: Chapter in Book/Report/Conference proceedingConference paperpeer-review

Abstract

Digital identity ecosystems are rapidly transforming the landscape of identity management. Self-Sovereign Identity (SSI) promises to enhance the individual’s agency over their identity; and related concepts form core parts of the EU’s upcoming eIDAS 2.0 regulation. Yet, this privacy-preserving technology must become less privacy-preserving for one overlooked party – credential issuers. Issuers are trusted to validate users’ attributes and attest to them. Thus, a compromised or misbehaving issuer is an immense threat, being able to issue credentials that allow them to impersonate anyone.

We address this concern by introducing Credential Issuance Transparency (CIT), a transparency framework for the issuance of identifying credentials. We take concepts from the Web PKI’s Certificate Transparency (CT), such as using public append-only logs, but adapt them to a privacy-preserving SSI world. In contrast to CT, the public logs of CIT disclose no information about a credential or its subject. Still, genuine subjects can monitor the log to discover mis-issued credentials that would allow an attacker to impersonate them; and empowered by non-interactive zero-knowledge proofs, verifiers can mandate correct logging.

CIT is practical. It adds a neglectable overhead of less than 2 ms to credential showing. Daily monitoring for mis-issuance requires less than 1 GB of data to be downloaded, and less than 10 s of computation to be invested. This makes CIT an important step towards SSI’s organizational acceptance and real-world feasibility.
Original languageEnglish
Title of host publicationNetwork and System Security. NSS 2024.
Subtitle of host publication18th International Conference, NSS 2024, Abu Dhabi, United Arab Emirates, November 20–22, 2024, Proceedings
EditorsHoubing Herbert Song, Roberto Di Pietro, Saed Alrabaee, Mohammad Tubishat, Mousa Al-kfairy, Omar Alfandi
PublisherSpringer
Pages107–126
Number of pages20
ISBN (Electronic)978-981-96-3531-3
ISBN (Print)978-981-96-3530-6
DOIs
Publication statusPublished - 14 Mar 2025
Event18th International Conference on Network and System Security, NSS 2024 - Abu Dhabi, United Arab Emirates
Duration: 20 Nov 202422 Nov 2024

Publication series

NameLecture Notes in Computer Science
Volume15564 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Conference on Network and System Security, NSS 2024
Country/TerritoryUnited Arab Emirates
CityAbu Dhabi
Period20/11/2422/11/24

Keywords

  • credential issuance
  • non-interactive zero-knowledge proofs
  • self-sovereign identity
  • transparency logs
  • unlinkability

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fields of Expertise

  • Information, Communication & Computing

Fingerprint

Dive into the research topics of 'Credential Issuance Transparency: A Privacy-preserving Audit Log of Credential Issuance'. Together they form a unique fingerprint.
  • A-SIT - Secure Information Technology Center Austria

    Posch, R. (Project manager), Oswald, M. E. (Other function), Payer, U. (Other function), Neuherz, E. (Other function), Ivkovic, M. (Attendee), Tauber, A. (Attendee), Reiter, A. (Attendee), Zefferer, T. (Attendee), Kreuzhuber, S. (Attendee), Rössler, T. (Other function), Mangard, S. (Attendee), Bratko, H. (Other function), Dietrich, K. (Attendee), Stranacher, K. (Attendee), Bonato, M. (Other function), Bauer, W. (Attendee), Orthacker, C. (Attendee), Wolkerstorfer, J. (Attendee), Zwattendorfer, B. (Attendee), Aigner, M. J. (Other function), Scheibelhofer, K. (Other function), Suzic, B. (Attendee), Knall, T. (Other function), Leitold, H. (Coordinator), Bratko, D. (Attendee), Dominikus, S. (Attendee), Lipp, P. (Attendee), Marsalek, A. (Attendee), Reimair, F. (Attendee), Feichtner, J. (Attendee) & Teufl, P. (Attendee)

    21/05/9931/12/24

    Project: Research area

Cite this